CMMC 2.0: cited answers and gap reviews
The Cybersecurity Maturity Model Certification protects Federal Contract Information and Controlled Unclassified Information in the Defense Industrial Base. Compliance Colleague covers Levels 1 to 3, NIST SP 800-171, CUI scoping and assessment preparation, practice by practice.
What it covers
- CMMC Levels 1, 2 and 3 and NIST SP 800-171
- CUI and FCI scoping
- SSP, POA&M and SPRS scoring
- C3PAO and DIBCAC assessments and self-assessment
- DFARS 252.204-7012 and 7021, and flow-down to subcontractors
Questions you can ask
- “Which of our systems are CUI assets, and which are security protection assets?”
- “Can a POA&M item close a Level 2 assessment, and which practices can't be on one?”
- “What do we have to flow down to a subcontractor under 252.204-7021?”
Every answer cites the CMMC 2.0 requirement, article or control it rests on, so you can check it in seconds.
What you can upload for review
- A network diagram checked for CUI enclave boundaries
- Your SSP checked practice by practice
- A POA&M (Excel) checked for items that can't be deferred
Files: PDF, Word, Excel or CSV, Visio (.vsdx), draw.io, or an image such as a screenshot. Choose a full review, a prioritized fix list (each gap with its fix and the evidence an assessor will expect) or a short summary, and download the result as Word or PDF.
Crosswalk CMMC 2.0 to other standards
With CMMC 2.0 in your plan you can compare it against any standard in the library and see where they align and exactly where they don’t. Common pairings:
Example answers
What it’s built from
Compliance Colleague carries the official text and checks its answers against it: 32 CFR Part 170: Cybersecurity Maturity Model Certification (CMMC) Program (US Department of Defense (via eCFR)); DFARS clauses 252.204-7012, -7019, -7020, -7021, -7024 and -7025 (48 CFR Part 252) (US Department of Defense (via eCFR)).
Re-checked every month for new versions, deadlines and penalty changes. Full list on the sources page.
More United States standards
NIST CSF · NIST SP 800-53 · NIST AI RMF · FedRAMP · HIPAA · CCPA / CPRA · ITAR · EAR · TSA Security Directives · Section 508
Research aid, not legal or audit advice, and not an audit opinion or certification. Verify findings against the official text before relying on them.